Skip to main content

Data Governance Settings and Roles

Open Data Governance → Settings & Integrations to control scanning and integrations.

Turn Data Governance on or off

Use Data Governance to control data governance scanning for the tenant.

When DLP is off:

  • Traffic is not scanned for Data Governance findings
  • Policies and behavioral rules cannot produce decisions
  • Overview and policy surfaces direct administrators back to Settings & Integrations

Turning Data Governance on enables scanning, but it does not monitor anything on its own. Coverage always comes from the policies you create — turn protection on, then add policies (or run the setup wizard) to choose what is monitored and where.

Only a Super Admin or Security Admin can change this setting.

DLP integrations

The integration panel shows the available sensitive-data detection provider and its data categories. The current connected integration is Google Sensitive Data Protection. Microsoft Purview, Amazon Macie, and Nightfall AI are shown as coming soon.

Adaptive Tuning

Adaptive Tuning is marked Experimental. When enabled, an administrator can start a retraining run and optionally require approval before publishing a successful result.

Automatic scheduled retraining is not currently available.

Capabilities marked coming soon

The Settings page also displays the following unavailable capabilities:

  • AI/NLP zero-shot entity detection
  • Custom patterns from the Settings page
  • Detector Feedback — coming soon: confirm or dismiss findings to tune detection for your tenant

Do not design a production workflow that depends on a control marked Coming Soon.


Roles and Permissions

RoleData Governance access
Super AdminView and manage settings, detectors, policies, and persona attachments
Security AdminView and manage settings, detectors, policies, and applicable persona governance
AuditorView Data Governance configuration and activity without changing it
Other rolesData Governance navigation is not available unless another assigned role grants the required permission

The ability to reveal masked sensitive values is controlled separately from general Data Governance access.